Back to home

Privacy Policy

Last updated: April 23, 2026

Overview

This policy explains how Invbill collects, uses, and shares information when you use our web application.

Information We Collect

  • Account and identity data: your user ID, email address, display name, and profile photo from Google sign-in, plus account credentials managed through Supabase Auth for email/password sign-in.
  • Session and authentication data: secure HTTP-only Supabase session cookies used to keep you signed in.
  • Invoice and settings data: invoice/receipt details you create (business data, client data, line items, totals, payment details, notes), plus saved business defaults and preferences.
  • Uploaded files: logo images uploaded to your account.
  • Payment data: selected credit pack, payment provider, amount, currency, purchase status, and provider customer, transaction, refund, and chargeback identifiers. Paystack or Paddle handles your payment details; Invbill does not store full card numbers.
  • Credit wallet data: promotional and purchased credit balances, expiry dates, reservations, usage records, and request IDs used to prevent duplicate charges.
  • Messaging connection data: the identifiers needed to link a private Telegram or WhatsApp chat to your account, delivery status, and workflow metadata. WhatsApp connection identifiers and messages are processed through Meta. Raw bot messages are cleared after the associated request completes.
  • Website analytics and attribution data: page visits, navigation events, referrers, landing pages, and campaign parameters such as UTM tags used to understand traffic sources and marketing performance.

How We Use Information

  • Authenticate users and secure access to dashboard features.
  • Create, store, update, and render invoices and receipts you manage in the app.
  • Generate structured invoice data from your prompts using AI features.
  • Process linked Telegram and WhatsApp requests to generate, confirm, and deliver documents to the account owner.
  • Process credit-pack purchases, refunds, and chargebacks.
  • Reserve and deduct credits, restore credits after eligible failures, and prevent duplicate charges.
  • Respond to support requests.
  • Measure website performance, understand acquisition channels, and improve marketing campaigns.

Third-Party Services

We use third-party infrastructure providers to operate the service:

  • Supabase (authentication, database, and file storage).
  • DeepSeek (AI generation from document prompts).
  • Telegram (linked private-chat document requests and delivery).
  • WhatsApp and Meta (linked private-chat document requests and delivery).
  • Upstash QStash (durable processing of bot updates).
  • Paystack (GHS credit-pack purchases and payment events).
  • Paddle (USD credit-pack purchases and payment events).
  • PostHog (website analytics, traffic attribution, and admin reporting).

These providers process data according to their own terms and privacy policies.

Cookies

We use essential cookies required for login sessions and authenticated requests. We currently do not use third-party advertising cookies, but we do use analytics storage to measure traffic, referrers, and campaign performance.

Data Retention

We retain account, document, and settings data while your account is active. You can request deletion of your account data by contacting support. Some billing-related records may be retained as required for financial, fraud, or legal compliance.

Security

We use access controls and signed authentication tokens to protect user data. No system is perfectly secure, but we work to reduce risk and improve safeguards over time.

Your Rights and Requests

For access, correction, or deletion requests, contact us at odin.dev7@gmail.com.

Policy Updates

We may update this policy from time to time. Material changes will be reflected by updating this page.